Netdev List
 help / color / mirror / Atom feed
* [PATCH] net: bpf_jit: fix an off-one bug in x86_64 cond jump target
@ 2011-12-17 21:39 Eric Dumazet
  2011-12-19 20:48 ` David Miller
  0 siblings, 1 reply; 2+ messages in thread
From: Eric Dumazet @ 2011-12-17 21:39 UTC (permalink / raw)
  To: David Miller; +Cc: netdev, Markus

From: Markus Kötter <nepenthesdev@gmail.com>

x86 jump instruction size is 2 or 5 bytes (near/long jump), not 2 or 6
bytes.

In case a conditional jump is followed by a long jump, conditional jump
target is one byte past the start of target instruction.

Signed-off-by: Markus Kötter <nepenthesdev@gmail.com>
Signed-off-by: Eric Dumazet <eric.dumazet@gmail.com>
---

libpcap expression to reproduce the bug :

"(tcp and portrange 0-1024) or (udp and portrange 1025-2048)"

 arch/x86/net/bpf_jit_comp.c |    4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/arch/x86/net/bpf_jit_comp.c b/arch/x86/net/bpf_jit_comp.c
index bfab3fa..7b65f75 100644
--- a/arch/x86/net/bpf_jit_comp.c
+++ b/arch/x86/net/bpf_jit_comp.c
@@ -568,8 +568,8 @@ cond_branch:			f_offset = addrs[i + filter[i].jf] - addrs[i];
 					break;
 				}
 				if (filter[i].jt != 0) {
-					if (filter[i].jf)
-						t_offset += is_near(f_offset) ? 2 : 6;
+					if (filter[i].jf && f_offset)
+						t_offset += is_near(f_offset) ? 2 : 5;
 					EMIT_COND_JMP(t_op, t_offset);
 					if (filter[i].jf)
 						EMIT_JMP(f_offset);

^ permalink raw reply related	[flat|nested] 2+ messages in thread

* Re: [PATCH] net: bpf_jit: fix an off-one bug in x86_64 cond jump target
  2011-12-17 21:39 [PATCH] net: bpf_jit: fix an off-one bug in x86_64 cond jump target Eric Dumazet
@ 2011-12-19 20:48 ` David Miller
  0 siblings, 0 replies; 2+ messages in thread
From: David Miller @ 2011-12-19 20:48 UTC (permalink / raw)
  To: eric.dumazet; +Cc: netdev, nepenthesdev

From: Eric Dumazet <eric.dumazet@gmail.com>
Date: Sat, 17 Dec 2011 22:39:08 +0100

> From: Markus Kötter <nepenthesdev@gmail.com>
> 
> x86 jump instruction size is 2 or 5 bytes (near/long jump), not 2 or 6
> bytes.
> 
> In case a conditional jump is followed by a long jump, conditional jump
> target is one byte past the start of target instruction.
> 
> Signed-off-by: Markus Kötter <nepenthesdev@gmail.com>
> Signed-off-by: Eric Dumazet <eric.dumazet@gmail.com>

Applied and queued up for -stable, thanks!

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2011-12-19 20:49 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2011-12-17 21:39 [PATCH] net: bpf_jit: fix an off-one bug in x86_64 cond jump target Eric Dumazet
2011-12-19 20:48 ` David Miller

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox